news.volyx.in

LastPass user vaults stolen in recent hack (blog.lastpass.com)

533 points by mikece · 1354 days ago · 315 comments on HN

Article summary

LastPass has reported a security incident where an unauthorized party gained access to a cloud-based storage environment, obtaining backups of customer vault data, including unencrypted website URLs and encrypted sensitive fields. The encrypted fields remain secured with 256-bit AES encryption and can only be decrypted with a unique encryption key derived from each user's master password. The company has notified law enforcement and relevant regulatory authorities and is taking measures to enhance security. Customers are advised to follow best practices and consider changing passwords as a precaution.

Main themes

  • Password Manager Security
  • Data Breach
  • Encryption
  • Phishing and Blackmail Risks
  • Cloud-Based Services
  • Security Best Practices

What commenters say

  • The exposure of unencrypted URLs and associated customer information poses a significant risk of targeted phishing attacks and blackmail.
  • The use of 256-bit AES encryption provides strong protection for sensitive fields, making brute-force attacks extremely difficult.
  • Storing URLs in plain text is a negligent practice that compromises the security of the password manager.
  • The incident highlights the importance of using unique and strong master passwords to prevent unauthorized access to encrypted data.
  • Some argue that the breach is not the worst-case scenario, as the encrypted data is still secure, while others believe it is a catastrophic failure due to the potential for blackmail and targeted attacks.
  • The lack of encryption for URLs and other metadata is seen as a major flaw in the password manager's design.
  • There are differing opinions on whether the benefits of cloud-based password management outweigh the risks of data breaches and unauthorized access.